Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Need to re-input the Pre-shared key to establish Sophos to FortiGate

We had a fortigate (initiator) to sophos (respond) site to site vpn via IPsec, and we configure our fortigate firewalls via fortimanager script.

The issue is every time a branch/s (Fortigate) got disconnected, we are required to re-input the pre-shared key in Sophos firewall in order to re-establish. Re-freshing  or bring down/up the phases in fortigate is not working. 

Even for adding new site/branch (also using FortiGate), we need to re-input the pre-shared key in Sophos firewall to able to establish the IPsec.

Our set up in Sophos is:

Remote Address gateway:  *

We have 3 site to site IPsec VPN using same wan in listening interface.

Branch A:

Local Subnet:      Remote Subnet

10.20.30.x           192.168.10.x

10.30.40.x

10.40.50.x

Branch B:

Local Subnet:      Remote Subnet

10.20.30.x           192.168.20.x

10.30.40.x

10.40.50.x

Branch C:

Local Subnet:      Remote Subnet

10.20.30.x           192.168.30.x

10.30.40.x

10.40.50.x

Firmware version: v19.5.1



This thread was automatically locked due to age.
Parents
  • Try not to use * (Wildcard) for IPsec Site to Site connections. 

    Use a DDNS / Fixed IP as a remote gateway. 

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Try not to use * (Wildcard) for IPsec Site to Site connections. 

    Use a DDNS / Fixed IP as a remote gateway. 

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data